2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48853 | CRITICAL | 9.5 | 0.3% | May 22, 2025 | An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a... |
| CVE-2024-48850 | HIGH | 7.5 | 0.4% | May 22, 2025 | Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue aff... |
| CVE-2024-54188 | MEDIUM | 5.3 | 5.8% | May 22, 2025 | Infoblox NETMRI before 7.6.1 has a vulnerability allowing remote authenticated users to read arbitrary files with root a... |
| CVE-2024-12093 | MEDIUM | 6.8 | 0.4% | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and ... |
| CVE-2024-25010 | HIGH | 8.8 | 0.2% | May 22, 2025 | Ericsson RAN Compute and Site Controller 6610 contains in certain configurations a high severity vulnerability where imp... |
| CVE-2024-9544 | MEDIUM | 6.4 | 0.2% | May 22, 2025 | The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,... |
| CVE-2024-57529 | MEDIUM | 6.1 | 0.4% | May 21, 2025 | Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary c... |
| CVE-2024-56428 | MEDIUM | 5.5 | 0.1% | May 21, 2025 | The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the C... |
| CVE-2024-23337 | MEDIUM | 6.5 | 0.4% | May 21, 2025 | jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning va... |
| CVE-2024-56429 | HIGH | 7.7 | 0.1% | May 21, 2025 | itech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users t... |
| CVE-2024-42922 | MEDIUM | 6.5 | 0.9% | May 21, 2025 | AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability. |
| CVE-2024-12561 | MEDIUM | 6.1 | 0.3% | May 21, 2025 | The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versi... |
| CVE-2024-45641 | MEDIUM | 6.5 | 0.2% | May 20, 2025 | IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate val... |
| CVE-2024-53359 | HIGH | 7.5 | 0.4% | May 20, 2025 | An issue in Zalo v23.09.01 allows attackers to obtain sensitive user information via a crafted GET request. |
| CVE-2024-5878 | MEDIUM | 6.4 | 0.3% | May 20, 2025 | Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled SimpleLightbox Jav... |
| CVE-2024-33939 | MEDIUM | 5.3 | 0.8% | May 19, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in masteriyo Masteriyo - LMS learning-management-... |
| CVE-2024-55063 | HIGH | 8.8 | 0.9% | May 19, 2025 | Multiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execut... |
| CVE-2024-51106 | MEDIUM | 4.6 | 0.2% | May 19, 2025 | A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation... |
| CVE-2024-4878 | — | — | — | May 19, 2025 | Rejected reason: Unused CVE record, incorrectly reserved |
| CVE-2024-13965 | — | — | — | May 17, 2025 | Rejected reason: wrong year |
| CVE-2024-13964 | — | — | — | May 17, 2025 | Rejected reason: wrong year |
| CVE-2024-13613 | HIGH | 7.5 | 0.4% | May 17, 2025 | The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2024-47893 | MEDIUM | 6.5 | 0.2% | May 17, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or w... |
| CVE-2024-40120 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_sto... |
| CVE-2024-53827 | HIGH | 7.5 | 0.3% | May 16, 2025 | Ericsson Packet Core Controller (PCC) contains a vulnerability where an attacker sending a large volume of specially cra... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now